SC-200 - Manage a Security Operations Environment - Section 1.3

Manage automated investigation and response, automatic attack disruption, Microsoft Sentinel automation rules, and playbooks.

Understand automated investigation and response (AIR) in Microsoft Defender XDR and how automatic attack disruption contains active attacks before an analyst intervenes. Configure Microsoft Sentinel automation rules to triage and route incidents, and build playbooks backed by Logic Apps connectors to orchestrate response actions across multiple services.

automated investigation and response (AIR)automatic attack disruption in Microsoft Defender XDRMicrosoft Sentinel automation rulesMicrosoft Sentinel playbooksLogic Apps connectors

Practice question for this objective

Free sampleManage a Security Operations Environmenthard

A security architect is enabling automatic attack disruption in Microsoft Defender XDR so that it can autonomously contain a confirmed human-operated ransomware attack across the estate. Endpoint signals are onboarded and automated investigation is running. The architect must ensure disruption is not blocked from taking its containment actions. Which configuration condition must be satisfied for the automatic disruption actions to be applied to the affected assets?

  • AA Microsoft Sentinel scheduled analytics rule must first be authored to detect the ransomware pattern before disruption can act on it
  • BDevices must keep an automation level enabled, because disruption is blocked where the device group is set to no automated remediation Correct
  • CAn analyst must approve each disruption action in the Action center before Microsoft Defender XDR applies it to a targeted device
  • DA custom detection rule must be created at the highest frequency so that disruption inherits its device-containment response action
Understand that automatic attack disruption uses the Defender for Endpoint automated response pipeline, so a no-automated-remediation device group blocks its containment actions. Automatic attack disruption is a built-in Microsoft Defender XDR capability that acts on high-confidence correlated signals to isolate devices and block accounts automatically. Because it applies device containment through the Microsoft Defender for Endpoint automated response path, a device group configured for no automated remediation prevents the disruption action from being applied. Keeping the automation level enabled lets disruption take its containment action.

Why A is wrong: Tempting because Sentinel often drives response, but attack disruption is a native Microsoft Defender XDR capability driven by high-confidence XDR signals, not by any Sentinel rule.

Why B is correct: Correct: disruption applies containment through the automated response pipeline, so a device group set to no automated remediation prevents the automatic actions from being applied.

Why C is wrong: Tempting because approvals exist for AIR remediations, but disruption is designed to act automatically without analyst approval; requiring approval would defeat its real-time purpose.

Why D is wrong: Tempting as custom detection rules can isolate devices, but disruption does not depend on a custom rule; it acts on built-in high-confidence correlated signals across XDR.

See more SC-200 practice questions, answers explained.

More in this domain

Back to all Manage a Security Operations Environment objectives, or the SC-200 cert hub.

Examworthy is not affiliated with or endorsed by Microsoft. Original, blueprint-aligned practice material only.